Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Hosted agents: sandboxes on Cloudflare Containers started from an intent | 1 | { |
| 2 | "$schema": "../../node_modules/wrangler/config-schema.json", | |
| 3 | "name": "g1t-runner", | |
| 4 | "account_id": "1e6f2cffa3f445920836e8ebe446bb58", | |
| 5 | "compatibility_date": "2026-09-26", | |
| 6 | "main": "./src/index.ts", | |
| 7 | "workers_dev": false, | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 8 | // One image (the base plus the runner binary), on three machine sizes. |
| 9 | // scripts/deploy.mjs deploys with each image set to the reference it | |
| 10 | // built and pushed (docs/DEPLOYING.md, "The runner's images"), so a | |
| 11 | // deploy builds nothing; "./Dockerfile" here is for building by hand. | |
| Hosted agents: sandboxes on Cloudflare Containers started from an intent | 12 | "containers": [ |
| 13 | { | |
| 14 | "class_name": "AttemptSandbox", | |
| 15 | "image": "./Dockerfile", | |
| 16 | "instance_type": "standard-1", | |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 17 | "max_instances": 20, |
| 18 | // A deploy replaces sandboxes. Ones that are busy are given this | |
| 19 | // long, in seconds, to finish first, so shipping g1t does not | |
| 20 | // kill agents in the middle of their work. | |
| 21 | "rollout_active_grace_period": 7200 | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 22 | }, |
| 23 | { | |
| 24 | // Workflow jobs with `runs-on: g1t-2core`: 2 vCPU, 8 GiB, 16 GB. | |
| 25 | "class_name": "Sandbox2Core", | |
| 26 | "image": "./Dockerfile", | |
| 27 | "instance_type": "standard-3", | |
| 28 | "max_instances": 10, | |
| 29 | "rollout_active_grace_period": 7200 | |
| 30 | }, | |
| 31 | { | |
| 32 | // Workflow jobs with `runs-on: g1t-4core`: 4 vCPU, 12 GiB, 20 GB. | |
| 33 | "class_name": "Sandbox4Core", | |
| 34 | "image": "./Dockerfile", | |
| 35 | "instance_type": "standard-4", | |
| 36 | "max_instances": 10, | |
| 37 | "rollout_active_grace_period": 7200 | |
| Hosted agents: sandboxes on Cloudflare Containers started from an intent | 38 | } |
| 39 | ], | |
| 40 | "durable_objects": { | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 41 | "bindings": [ |
| 42 | { "name": "SANDBOX", "class_name": "AttemptSandbox" }, | |
| 43 | { "name": "SANDBOX_2CORE", "class_name": "Sandbox2Core" }, | |
| 44 | { "name": "SANDBOX_4CORE", "class_name": "Sandbox4Core" } | |
| 45 | ] | |
| Hosted agents: sandboxes on Cloudflare Containers started from an intent | 46 | }, |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 47 | "migrations": [ |
| 48 | { "tag": "v1", "new_sqlite_classes": ["AttemptSandbox"] }, | |
| 49 | { "tag": "v2", "new_sqlite_classes": ["Sandbox2Core", "Sandbox4Core"] } | |
| 50 | ], | |
| Hosted agents: sandboxes on Cloudflare Containers started from an intent | 51 | "services": [ |
| 52 | { "binding": "IDENTITY", "service": "g1t-identity" }, | |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 53 | { "binding": "REPOS", "service": "g1t-repos" }, |
| 54 | { "binding": "WORK", "service": "g1t-work" }, | |
| Integrations: your own model provider, alerts that open issues, tickets agents read | 55 | { "binding": "BILLING", "service": "g1t-billing" }, |
| GitHub Actions on g1t, part two: running workflows | 56 | { "binding": "INTEGRATIONS", "service": "g1t-integrations" }, |
| Deployments: a preview for every pull request, production on g1t.page | 57 | { "binding": "ACTIONS", "service": "g1t-actions" }, |
| Project dependencies: addresses, preview stacks, Affects, and agents who know | 58 | { "binding": "DEPLOYMENTS", "service": "g1t-deployments" }, |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 59 | { "binding": "PROJECTS", "service": "g1t-projects" }, |
| 60 | // The context hub: the Context section every agent run starts with. | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 61 | { "binding": "CONTEXT", "service": "g1t-context" }, |
| 62 | // The event bus: abuse.flagged, when a sandbox looks like it is mining. | |
| 63 | { "binding": "EVENTS", "service": "g1t-events" } | |
| Hosted agents: sandboxes on Cloudflare Containers started from an intent | 64 | ], |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 65 | // A sweep for lifecycle steps whose trigger was missed or whose sandbox |
| Merge branch 'worktree-agent-ac5b181a013e54348' | 66 | // died before reporting, which also starts queued nightly backups. |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 67 | "triggers": { "crons": ["*/5 * * * *"] }, |
| Acceptance checks in sandboxes, line comments and review verdicts | 68 | // Events it reacts to: a pull request ready for review, or its head moving. |
| 69 | "queues": { | |
| 70 | "consumers": [{ "queue": "g1t-events-runner", "max_batch_size": 20, "max_batch_timeout": 1 }] | |
| 71 | }, | |
| Hosted agents: sandboxes on Cloudflare Containers started from an intent | 72 | "vars": { |
| Models per workspace: several providers, routed by kind of work | 73 | // Each workspace chooses where its agents' model spend goes: its own |
| 74 | // provider (under Integrations) or g1t's hosted models, paid from its | |
| 75 | // credit. While billing takes no real money, hosted models are open | |
| 76 | // only to these workspaces; once it does, to every workspace. | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 77 | "HOSTED_AGENT_WORKSPACES": "flagon-io", |
| Merge branch 'model-routing' | 78 | // How g1t routes agent work: "Auto" (AgentRouting and route in |
| 79 | // src/model-env.ts). Nobody assigning an agent has to choose; a workspace | |
| 80 | // can still choose a tier per kind of work under Integrations. "tiers": the | |
| 81 | // catalogue, the model behind small (fast), large (standard) and frontier | |
| 82 | // (most capable); "modelName" is shown to people, "model" is sent to the | |
| 83 | // provider, "price" (dollars per million tokens) is for estimates only. | |
| 84 | // "tasks": the tier each kind of job starts on, or "change" to size the | |
| 85 | // change a review reads ("smallChange" or less and nothing sensitive: small; | |
| 86 | // more than "largeChange": frontier). "frontierLabels", "largeLabels" and | |
| 87 | // "smallLabels" move work by its issue's labels. A failed attempt goes one | |
| 88 | // tier up and "frontierAfter" failures in a row to frontier; "learning" | |
| 89 | // steps work down or up by the repository's own recent runs of the kind. | |
| 90 | "AGENT_ROUTING": "{\"tiers\":{\"small\":{\"modelName\":\"Claude Haiku 4.5\",\"model\":\"claude-haiku-4-5-20251001\",\"price\":{\"input\":1,\"output\":5,\"cacheRead\":0.1,\"cacheWrite\":1.25}},\"large\":{\"modelName\":\"Claude Sonnet 5.5\",\"model\":\"claude-sonnet-5-5\",\"price\":{\"input\":2,\"output\":10,\"cacheRead\":0.2,\"cacheWrite\":2.5}},\"frontier\":{\"modelName\":\"Claude Opus 5.5\",\"model\":\"claude-opus-5-5\",\"price\":{\"input\":4,\"output\":20,\"cacheRead\":0.2,\"cacheWrite\":5}}},\"tasks\":{\"implement\":\"large\",\"revise\":\"large\",\"answer\":\"small\",\"review\":\"change\",\"update\":\"small\",\"plan\":\"large\"},\"smallChange\":{\"files\":10,\"lines\":200},\"largeChange\":{\"files\":60,\"lines\":3000},\"largeLabels\":[\"security\"],\"frontierLabels\":[\"architecture\"],\"smallLabels\":[\"documentation\",\"docs\",\"typo\"],\"frontierAfter\":2,\"learning\":{\"window\":20,\"minRuns\":5,\"stepDownAt\":0.9,\"stepUpAt\":0.5}}", | |
| Integrations: your own model provider, alerts that open issues, tickets agents read | 91 | // Where sandboxes send model requests, with a token for their run. |
| 92 | // The proxy holds the keys: g1t's gateway's, or the workspace's own. | |
| 93 | "MODELS_URL": "https://models.g1t.sh", | |
| g1t agents: model menu and optional AI Gateway routing | 94 | // Set to a Cloudflare AI Gateway id to route model traffic through it. |
| Integrations: your own model provider, alerts that open issues, tickets agents read | 95 | // Used only when MODELS_URL is unset. |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 96 | "AI_GATEWAY_ID": "g1t", |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 97 | "CLOUDFLARE_ACCOUNT_ID": "1e6f2cffa3f445920836e8ebe446bb58", |
| 98 | // Guardrails' network list is enforced by starting sandboxes without | |
| 99 | // internet and passing their HTTP(S) through this Worker. "off" opens | |
| 100 | // every sandbox's network again, whatever its guardrails say. | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 101 | "EGRESS": "enforce", |
| 102 | // Sandboxes stop themselves when they look like they are mining | |
| 103 | // (crates/runner abuse.rs). "off" turns the CPU watch off; miners | |
| 104 | // named in commands are refused either way. | |
| Merge branch 'worktree-agent-ac5b181a013e54348' | 105 | "ABUSE_WATCH": "on", |
| 106 | // Nightly backups (src/backup.ts): each sweep starts this many of the | |
| 107 | // backups the repos service queued, with at most BACKUPS_RUNNING at | |
| 108 | // once. "0" starts none. | |
| 109 | "BACKUPS_PER_SWEEP": "4", | |
| 110 | "BACKUPS_RUNNING": "6" | |
| Hosted agents: sandboxes on Cloudflare Containers started from an intent | 111 | }, |
| 112 | "observability": { "enabled": true } | |
| 113 | } |
This file's history is long; its oldest lines are credited to the oldest commit read.